Virus

How to remove “Virus:Win32/Yaz.A”?

Malware Removal

The Virus:Win32/Yaz.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Virus:Win32/Yaz.A virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Installs OpenCL library, probably to mine Bitcoins
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Virus:Win32/Yaz.A?


File Info:

crc32: 851DB5AC
md5: 143510dc0289122a43733b856e3de841
name: 143510DC0289122A43733B856E3DE841.mlw
sha1: 1dc712ab1ce2ad36df79e6905ca025301ac486fd
sha256: f44b39ccd6f1b9dd2bb05c19b7c2240019e3ed0912efb3a292671b76db82ed6a
sha512: 56c3af2fa9d2620090eef03140819115fbc5303653325fb80af4ba22d4fbb9de1f5c9e84dbbb48759b92125812db81e415ff8fbf5a34be6c6e4fa6b5fc15876a
ssdeep: 3072:Q2L+cvwVw5YQnxAb6BvZcHLPm+Q+owZR8KNo0:Q+15NRGznTv8Ku0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Virus:Win32/Yaz.A also known as:

BkavW32.yaExtractorDA.PE
K7AntiVirusTrojan ( 005451b81 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.94
CynetMalicious (score: 100)
CAT-QuickHealW32.Yaz.A
ALYacGeneric.Ransom.Xorist.D28AEBD4
CylanceUnsafe
ZillyaVirus.Yazzz.Win32.1
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaVirus:Win32/Xorist.7252444f
K7GWTrojan ( 005451b81 )
Cybereasonmalicious.c02891
BaiduWin32.Virus.Yaz.a
CyrenW32/Yaz.A
SymantecRansom.CryptoTorLocker
ESET-NOD32Win32/Agent.OVQ
APEXMalicious
AvastWin32:Yaz-A
ClamAVWin.Trojan.Yaz-1
KasperskyVirus.Win32.Yaz.a
BitDefenderGeneric.Ransom.Xorist.D28AEBD4
NANO-AntivirusVirus.Win32.Yaz.jgeya
ViRobotWin32.YAZ.A
MicroWorld-eScanGeneric.Ransom.Xorist.D28AEBD4
TencentVirus.Win32.Yaz.b
Ad-AwareGeneric.Ransom.Xorist.D28AEBD4
SophosMal/Generic-R + W32/Yaz-A
ComodoTrojWare.Win32.Kryptik.ER@4o1ar2
BitDefenderThetaAI:FileInfector.9095DFEB0B
VIPREVirus.Win32.Yaz.a (v)
TrendMicroPE_YAZ.A
McAfee-GW-EditionW32/Yaz.a
FireEyeGeneric.mg.143510dc0289122a
EmsisoftGeneric.Ransom.Xorist.D28AEBD4 (B)
SentinelOneStatic AI – Malicious PE
JiangminWin32/Yaz.a
WebrootW32.Malware.Gen
AviraW32/Yazz.aumnb
MicrosoftVirus:Win32/Yaz.A
AegisLabTrojan.Win32.Xorist.lpjq
GDataGeneric.Ransom.Xorist.D28AEBD4
AhnLab-V3Win32/Yaz.X796
Acronissuspicious
McAfeeW32/Yaz.a
MAXmalware (ai score=100)
VBA32Virus.Yazz
MalwarebytesRansom.Xorist
PandaW32/Yazz.A
TrendMicro-HouseCallPE_YAZ.A
RisingTrojan.Ransom!1.690B (CLOUD)
YandexTrojan.GenAsa!WMPZeg7Kq7U
IkarusTrojan-Ransom.Xorist
FortinetW32/Xorist.DD8C!tr.ransom
AVGWin32:Yaz-A
Paloaltogeneric.ml

How to remove Virus:Win32/Yaz.A?

Virus:Win32/Yaz.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment